Join us

ContentUpdates and recent posts about Sigstore..
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Manus AI Launches ‘Wide Research,’ Pitting 100-Agent Swarms Against ‘Deep Research‘ from Google and OpenAI

Manus just droppedWide Research—a swarm of 100+ AI agents, each spun up as a Turing-complete VM. They don’t follow orders. They solve massive tasks in parallel, straight from natural language prompts. Forget rigid chains of command. These agents don’t play roles—they run jobs. No hierarchies. No br.. read more  

Manus AI Launches ‘Wide Research,’ Pitting 100-Agent Swarms Against ‘Deep Research‘ from Google and OpenAI
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Blue‑Green Deployment in 1 diagram and 195 words

Blue-Green deployment runs two matching environments so you can flip traffic with zero downtime—and yank it back fast if something breaks. Kubernetes + IstioandSpinnakerhandle the heavy lifting. They steer traffic between versions and keep infra lean... read more  

Blue‑Green Deployment in 1 diagram and 195 words
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives

Perplexity AI’s stealth crawling behavior includes modifying user agents and source ASNs to avoid website blocks, highlighting the importance of transparent bot behavior... read more  

Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Project Ire autonomously identifies malware at scale

Microsoft just droppedProject Ire, an autonomous AI that tears through software like a experienced reverse engineer. It decompiles, analyzes, classifies malware—all on its own. Under the hood: LLMs, decompilers, and a tool-use API running the show. On public Windows driver datasets, it scored0.98 p.. read more  

Project Ire autonomously identifies malware at scale
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

How to automatically disable users in AWS Managed Microsoft AD based on GuardDuty findings

AWS just dropped a new threat-response setup that tiesGuardDuty,EventBridge,Step Functions, andSystems Manager Run Commandinto one clean pipeline. The goal? Hunt for EC2 threats and lock downActive Directoryaccounts—automatically. GuardDuty kicks off the flow when it spots trouble. From there, Even.. read more  

How to automatically disable users in AWS Managed Microsoft AD based on GuardDuty findings
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Writing an internal Terraform provider from A to Z

Typeform rolled their ownTerraform providerto wrangle runtime data through an internal API. Built with HashiCorp’sGo SDK, the official scaffolding framework, and wired up withacceptance testsfor full lifecycle muscle. They skipped the publicTerraform Registryentirely. Instead, they shipped provider.. read more  

Writing an internal Terraform provider from A to Z
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Building on the foundation of OpenTelemetry eBPF Instrumentation: what’s new in Grafana Beyla 2.5

Grafana Beyla 2.5 goes all-in on upstreamOpenTelemetry eBPF Instrumentation, baking it right into the core. This release addsauto-instrumentation for MongoDB and JSON-RPC,manual spans in Go, and tightertrace correlation for NodeJS. New in town:survey mode. Think lightweight service discovery—no ful.. read more  

Building on the foundation of OpenTelemetry eBPF Instrumentation: what’s new in Grafana Beyla 2.5
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

🚨 Azure Service Health Built-In Policy (Preview) – Now Available! 

Microsoft just droppedAzure Service Health Built-In Policy(Preview). It lets teams push Service Health alerts across every Azure subscription—automatically—using Azure Policy. No more piecemeal setup. It folds in AMBA lessons, supports custom rules and action groups, and locks in alert coverage at .. read more  

🚨 Azure Service Health Built-In Policy (Preview) – Now Available! 
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

From Manual Testing to AI-Generated Automation: Our Azure DevOps MCP + Playwright Success Story

A team wired up Azure DevOps’MCP serverwithGitHub Copilotto crank outPlaywrightend-to-end tests from manual test cases. They now run tests on demand from Azure Test Plans, convert entire test suites in bulk, and drop the results into CI pipelines—no hand-holding required. System shift:AI's not just.. read more  

From Manual Testing to AI-Generated Automation: Our Azure DevOps MCP + Playwright Success Story
Link
@faun shared a link, 9 months, 2 weeks ago
FAUN.dev()

Introducing Approvals in Pulumi ESC

Pulumi ESC just leveled up withApprovals—structured reviews for environment config changes, straight from Console, CLI, SDK, or VS Code. Think pull requests, but for your infra settings. No more YOLO updates. Teams can now lock down config changes with required sign-offs. More control. Cleaner logs.. read more  

Introducing Approvals in Pulumi ESC
Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.